rights-explainer
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill functions as an autonomous auditor for legal aid portals and information systems, evaluating them for plain-language quality and legal accuracy.\n- [COMMAND_EXECUTION]: The skill reads standard dependency and configuration files (e.g., package.json, requirements.txt, go.mod) to identify the platform's tech stack and search infrastructure. This is standard behavior for an analysis agent.\n- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it processes untrusted data from the analyzed codebase (HTML, markdown, database records). However, it lacks high-risk capabilities such as network access or administrative shell access. Ingestion points: codebase and legal content files. Boundary markers: absent. Capability inventory: local file read and local telemetry file append. Sanitization: absent.\n- [DATA_EXFILTRATION]: No network communication or exfiltration of sensitive information was detected.\n- [SAFE]: The skill contains a telemetry feature that appends execution metadata to a local file in the project memory directory (~/.claude/projects/skill-telemetry.md). This is a restricted local write operation for performance tracking.
Audit Metadata